Published Last updated Written and reviewed by the Resale Intelligence team
On this page
Add or remove single permissions for one person without changing their role. Deny beats allow, you give only what you hold and conflicting pairs need the owner.
- Who can do this:
- Owner, Store Admin (role defaults; the owner can change them)
Sometimes a role almost fits a staff member's job but has one or two permissions too few or too many. Instead of choosing a bigger role, adjust single permissions for that person.
Three choices for each permission
| Choice | Effect |
|---|---|
| Role default | Follows the role's default |
| Allow | Adds this permission even if the role doesn't have it |
| Deny | Removes this permission even if the role has it |
If a permission is both allowed and denied, deny always wins.
Adjust one person's permissions
Open Team and tap Edit on the staff member's row.
Enter your own password again if asked.
Open Fine-tune individual permissions (advanced).
Find the permission and choose Allow or Deny.
Tap Save.
Limits
-
You can only give permissions you hold. A store admin can't grant a permission they don't have.
-
Owner-only permissions, such as managing the plan, security settings, pricing controls and the full store export, show a lock icon. Store admins can't grant them. An owner can, but the access review then lists it as a finding.
-
Permissions marked "not available yet" belong to features that aren't ready. You can set them, but they have no effect yet.
-
Sensitive permissions bring 2FA. If you give a cashier a permission such as voiding or recording cash, that person must turn on 2FA within the grace period. See Who must use 2FA and how long they have.
Conflicting permissions
Some pairs shouldn't sit with one person, because that person could both do and check the same work.
| Pair | Why |
|---|---|
| Record cash movements and Count and verify cash | Whoever records cash shouldn't count and verify it |
| Manage team and permissions and Review team access | Whoever grants access shouldn't review it |
| Change customer risk level and Buy items | Whoever buys shouldn't lower the risk level of the customers they buy from |
If an adjustment creates a conflicting pair the role didn't already have, a store admin can't save it. An owner can, by entering a reason in Reason for granting conflicting permissions (only when warned), and the reason is kept in the audit log.